Oauth permissions using transition:generic
did:plc:pddp4xt5lgnv2qsegbzzs4xg opened this 21d ago 1 comments
did:plc:pddp4xt5lgnv2qsegbzzs4xg opened 21d ago
I noticed this currently is using transition:generic for the oauth permissions.
This blanket allows all permissions to the account, which is now considered bad practice.
Consider using just the minimum app.bsky.actor.profile you need to get their profile information.
Heres some reference https://underreacted.leaflet.pub/3mjfozhlhys2z
No activity yet.